What the program is
Anthropic puts safeguards on Claude. By default, the safeguards block some cybersecurity requests. A defender uses some of these skills to read malware, and an attacker can use the same skills to write it. Anthropic calls this dual-use work.
A security team uses the Cyber Verification Program to ask Anthropic to review its work. If Anthropic approves the application, Anthropic adjusts the safeguards for that team's organization. The adjustment covers only the use cases in the application.
What the approval allows and what it blocks
No longer blocked by default
- Basic penetration testing
- Red teaming
- Bug bounty research
Still blocked for everyone
- Command-and-control infrastructure
- Mass data theft
- Ransomware development
The approval covers one Anthropic organization and only the use cases in our application. Anthropic's Usage Policy still applies, and Anthropic monitors the account. Anthropic can narrow the approval or revoke it.
The approval covers our research only. Anthropic did not test Vigilance or compare it with other tools. Anthropic reviewed our application and adjusted the safeguards for the use cases we described.
Why we applied
Vigilance catches supply chain attacks. It shows the one file in an update that can do something new. If no file can do something new, Vigilance stays quiet. To build and test it, we study real attacks.
- Find the package. We get a malicious package from a public registry.
- Analyze the package. We find what each file does.
- Publish the facts. We write an advisory, for example VIGI-001-2026.
Step 2 is dual-use work. A defender and an attacker can send the same request, for example "explain how this backdoor loader works". The default safeguards can block that request.
What changes for you
The product does not change. Vigilance does not send your files to Claude or to any other service. Pro runs offline and uses no network.
Our research changes. We can now use Claude for dual-use analysis of malicious packages. The results go into the attack library and our advisories.
About Vigilance
Phended, a Canadian cybersecurity company, makes Vigilance. Vigilance catches supply chain attacks before they cause damage. It sends one alert, and only when the attack is real.